Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

CSVForm Remote Arbitrary Command Execution Vulnerability

CSVForm is a Perl cgi script for Linux and Unix systems used to format input from a cgi form into a comma separated value text file, commonly used for later import into a database.

CSVForm fails to properly validate user-supplied input passed as the file variable. This input is later used to open a file for writing. Maliciously formed URLs submitted to the script may contain shell commands which will be run with the privilege level of the webserver (ie, user 'nobody'). As a result, an attacker may execute arbitrary code on the vulnerable system.







 

Privacy Statement
Copyright 2008, SecurityFocus